Home / Sep 13, 2026 / Story
0
#7 BleepingComputer general September 11, 2026 at 17:26 UTC

Passkey-themed phishing attacks lead to Microsoft 365 data theft

By Lawrence Abrams

AI Summary

Microsoft has identified threat actors linked to ShinyHunters, Helix, and other extortion groups using passkey- and SSO-themed social engineering lures to compromise corporate Microsoft 365 accounts and exfiltrate data. The attacks exploit user trust in modern authentication flows — specifically passkey prompts — as phishing vectors, representing an evolution beyond traditional credential-harvesting pages. Security teams should update awareness training to cover passkey-themed phishing as a novel and growing attack vector.

Relevance score: 80.0/100

# More from September 13